We are in the process of moving from Exchange 2016 to Exchange Online and are having problems with getting SecureMail to work with migrated mailboxes. Everything seems to go well, it accepts the initial credentials, redirects the user to the Modern Authentication login page for Microsoft Online. It then appears to accept the Office 365 Credentials but gets stuck with a box saying 'Verifying' before returning the error 'Oops! We've encountered an issue during authentication'
We have setup secure mail to tunnel into our network first and connect to Office 365 from there, as we have location specific conditional access policies enabled for our Office 365 accounts that mean that it only works when connected from our network. If I turn off those policies and set SecureMail's network connection policy to 'Unrestricted', I can successfully sign-in to the mailbox and download the emails. With the Conditional Access policies enabled, I can sign-in to same account in OWA, through the SecureWeb app, without issue. As such, there appears to be an issue with the SecureMail tunnelled connection through the gateway (I've tried all of the different Tunnelled options).
there might be an annoying bug in SM 19.4.5.16 and maybe other versions. Users did complain that attachments aren`t shown. I could not believe that at first and tracked different messages and compared sizes. Then I experienced it by myself. An e-mail with 3 attachments (.PNG - normal size etc.) had no attachments although they are shown in Outlook and other e-mail clients.
This problem appears with Exchange 2010 and 2016. If the user forwards the problem mail to his own account, the attachments appear in the mail. I could not resolve the concrete circumstances, but it must have something to do with Secure Mail because other clients don`t have this problem. I can`t think of any settings in the MDX file or somewhere else that would cause those problems.
Hi Tobias,
E-mail app can use other endpoints like EWS and Graph to fetch emails apart from Active Sync so, this issue might not be observed while using other endpoints. To investigate this issue further in detail, please get in touch with your admin and then raise a request to Citrix customer support.
I just wanted to mention that after months of waiting this easy to replicate bug hasn`t been fixed. The new features within Secure Mail haven`t been helpful for me or my users. Instead of adding continuously new features this and other bugs should be fixed first. I couldn`t find any app witch the same bug. It`s a shame that an e-mail app doesn`t properly view attachments.
We use secure mail on our iPdads and iPhones. When our employees are on the move (by train or similar) it happens that there is no internet available or the devices are deliberately used in flight mode.
I (or rather Citrix support) figured this out; we had not enabled Microsoft Modern Authentication (OAuth) in Secure Mail, and Microsoft has now disabled Basic Authentication for all tenants starting October 1 2022 (but apparently this didn't take effect until a few weeks later). Turning on OAuth in Secure Mail app settings fixed this (in my case an account deletion was necessary first to get the new account sign-in info accepted, probably due to differing UPN vs. e-mail settings).
Secure Web cannot open the page because the address is invalid.
If I don't set up the mail account via Citrix, but as an Exchange account in the Passwords and Accounts section, the link is accepted and the Teams app starts the meeting.
3. On XenMobile, create a new Exchange device policy. Following is an example of an exchange device policy for IOS devices. In the User and Email Address fields, enter $user.pager. Please populate other settings as per your current setup.
5. Remove the user from other delivery group and add to this new delivery group. You might have to refresh the policy in secure hub and / or just reboot the device to get the new settings of new device policy.
Please note that this new device policy needs to be added to your new delivery group along with other device policies that you currently have in place. This device policy will just add the additional mailbox (shared mailbox) to your primary mailbox. So you still need other device policies that sets up your primary mailbox.
Citrix Secure Mail is a powerful email application developed by Citrix, designed to provide a secure and customizable email experience. With this app, users can easily manage their emails, calendars, and contacts from multiple accounts, including personal and business. The app ensures the safety and security of personal data, making it ideal for enterprise and BYOD programs. Citrix Secure Mail works seamlessly with other Citrix apps such as Citrix Files, QuickEdit, Skype for Business, and GoToMeeting. The app can be customized according to the user's needs and preferences, and with Citrix Endpoint Management, it can be managed with security policies that meet organizational needs. Additionally, the app has the ability to report phishing emails, further enhancing its security features.
Atlantic Health System provides several options for secure, convenient access to our network from remote environments, exclusively for our team members and partners. Many of these services require multi-factor authentication (MFA).
wdt_ID Brief Description of Issue Brief Description of Fix Applicable Product Versions Affected (if known) Link to supplemental Support Article(s) 1 When opening PDF links through Secure Web Adobe does not appear as an "Open-in" option. The PDF is actually embedded in HTML, which is why Adobe is not given as an option. 2 If a users device is deleted from XenMobile Server, you are unable to enroll the iOS/Android device again. Perform a migration from XDM 9 to XMS 10.x using the latest XenMobile migration tool. 3 When users try to enrol or download apps they receive error "Cannot complete request" in Secure Hub. Upgrade to XenMobile Server 10.5 Rolling Patch 2. 4 Emails are received in Secure Mail on Android 7 but notifications do not show on the screen. In Secure Mail check the "Check frequency" setting. The preferred value is "Auto". Next check notifications are switched on for Secure Mail by navigating to "Settings -> Notifications". Also check to make sure power saving mode is not switched on, which may prevent notifications from showing. This behaviour in power saving mode can be modified to show notifications for Secure Mail. 5 Policies and applications do not push to iOS devices from XenMobile 10.5 configured with a proxy server. APNS traffic does not work with Auth and can be configured without authentication as HTTP or SOCKS. 6 You cannot bind secure LDAP on XenMobile. If you have more than one Domain Controller, install each certificate on XenMobile Server. Also enter the Domain Controller's FQDN in the primary and secondary server fields in LDAP configuration on XMS. Citrix XenMobile 10.6. 7 Windows phone partially enrols on XenMobile. The device is listed as managed on the XenMobile console but all the properties for the device are not listed. Make sure the XenMobile Server certificate has not expired. If it has, renew it. 8 Secure Mail prompts for a pin such as when the application sleeps or wakes. This is due to iOS intervention. As iOS puts applications such as Secure Mail to sleep such as when the battery is low. This can also cause notifications to not be delivered until the user brings Secure Mail to the foreground by explicitly opening it. 9 "Incorrect credentials" error received when trying to enrol a device even though the credentials are correct. Test on other users to see if this is specific to certain accounts. On the affected accounts, within Active Directory, check the samAccountName/UPN is correct. 10 Un-enrolled devices still show as managed. This is expected behaviour. When a device is un-enrolled client side, the device will remain as managed on XenMobile Server due to the device no longer communicating with XMS. This is not a concern because the secured data that was on the device will no longer be accessible. In a future release, there may be a change to XenMobile that prevent un-enrolling until the device has connectivity to XMS. table.wpDataTable table-layout: fixed !important; table.wpDataTable td, table.wpDataTable th white-space: normal !important; table.wpDataTable td.numdata text-align: right !important;
In Provider bundle identifier enter com.citrix.NetScalerGateway.macos.app.vpnplugin. This is the bundle identifier of the network extension contained in the Citrix Secure Access client binary.
To associate the VPN profile to a specific App on the device, you must create an App Inventory policy and a credentials provider policy by following this guide - -app-vpn-with-xenmobile-and-citrix-vpn/
If the end users are presented with the Download EPA plug-in button in the authentication window of Citrix Secure Access, it means that the content security policy on the NetScaler appliance is blocking invocation of the URL com.citrix.agmacepa://. The admins have to modify the content security policy such that com.citrix.agmacepa:// is allowed.
df19127ead